Aggregator
《2024网安市场年报》数据中有意思的地方
10 months 2 weeks ago
《2024网安市场年报》数据中有意思的地方
10 months 2 weeks ago
TikTok ‘Infinite Money Glitch’ — Idiots Chased by JPMorgan
10 months 2 weeks ago
Dimon’s dollars (not yours): No, Chase Bank isn’t going to let you cash bad checks. It’s fraud—no matter what X and TikTok tell you.
The post TikTok ‘Infinite Money Glitch’ — Idiots Chased by JPMorgan appeared first on Security Boulevard.
Richi Jennings
HikkI-Chan Has Allegedly Leaked the Database of FRYP
10 months 2 weeks ago
HikkI-Chan Has Allegedly Leaked the Database of FRYP
Dark Web Informer
CVE-2008-6391 | Nexusjnr Jbook main.asp sql injection (EDB-32635 / XFDB-47033)
10 months 2 weeks ago
A vulnerability has been found in Nexusjnr Jbook and classified as critical. This vulnerability affects unknown code of the file main.asp. The manipulation leads to sql injection.
This vulnerability was named CVE-2008-6391. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
KEV + CWE = Attack Vector ❤️🔥
10 months 2 weeks ago
Learn how to cross-reference Known Exploit Vulnerabilities (KEV) against CWE to find the best attack vectors to use during security testing.
The post KEV + CWE = Attack Vector ❤️🔥 appeared first on Dana Epp's Blog.
Dana Epp
微软CEO纳德拉自降薪酬,员工工资与安全直接挂钩
10 months 2 weeks ago
由于微软强劲的市场表现,萨蒂亚·纳德拉 (Satya Nadella) 2024 财年的薪酬远远超过 2023 年。
SecWiki News 2024-10-29 Review
10 months 2 weeks ago
今日暂未更新资讯~
更多最新文章,请访问SecWiki
更多最新文章,请访问SecWiki
mommy of OG N*ggers is Allegedly Selling Initial Access to N4 Telecom
10 months 2 weeks ago
mommy of OG N*ggers is Allegedly Selling Initial Access to N4 Telecom
Dark Web Informer
CVE-2013-7030 | Cisco Unified Communications Manager TFTP Service SPDefault.cnf.xml UseUserCredential cryptographic issues (EDB-30237 / XFDB-89649)
10 months 2 weeks ago
A vulnerability was found in Cisco Unified Communications Manager. It has been declared as problematic. This vulnerability affects unknown code of the file SPDefault.cnf.xml of the component TFTP Service. The manipulation of the argument UseUserCredential leads to cryptographic issues.
This vulnerability was named CVE-2013-7030. The attack can be initiated remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
vuldb.com
CVE-2014-9426 | PHP 5.6.4 fileinfo apprentice_load code (Nessus ID 81418 / ID 167612)
10 months 2 weeks ago
A vulnerability was found in PHP 5.6.4. It has been declared as problematic. This vulnerability affects the function apprentice_load of the component fileinfo. The manipulation leads to code.
This vulnerability was named CVE-2014-9426. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2020-8549 | Strong Testimonials Plugin up to 2.40.0 on WordPress Stored cross site scripting (ID 156369)
10 months 2 weeks ago
A vulnerability was found in Strong Testimonials Plugin up to 2.40.0 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting (Stored).
This vulnerability is handled as CVE-2020-8549. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-14318 | Samba privileges assignment
10 months 2 weeks ago
A vulnerability was found in Samba. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to incorrect privilege assignment.
The identification of this vulnerability is CVE-2020-14318. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2021-40812 | libgd GD Graphics Library up to 2.3.2 gdGetBuf/gdPutBuf out-of-bounds
10 months 2 weeks ago
A vulnerability was found in libgd GD Graphics Library up to 2.3.2. It has been declared as problematic. This vulnerability affects the function gdGetBuf/gdPutBuf. The manipulation leads to out-of-bounds read.
This vulnerability was named CVE-2021-40812. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-24329 | JetBrains Kotlin up to 1.5.x Gradle Project inclusion of functionality from untrusted control sphere
10 months 2 weeks ago
A vulnerability was found in JetBrains Kotlin up to 1.5.x. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Gradle Project Handler. The manipulation leads to inclusion of functionality from untrusted control sphere.
This vulnerability is known as CVE-2022-24329. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-24329 | Oracle Communications Pricing Design Center 12.0.0.4/12.0.0.5 REST Services Manager locking
10 months 2 weeks ago
A vulnerability has been found in Oracle Communications Pricing Design Center 12.0.0.4/12.0.0.5 and classified as critical. Affected by this vulnerability is an unknown functionality of the component REST Services Manager. The manipulation leads to improper locking.
This vulnerability is known as CVE-2022-24329. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-24329 | Oracle Communications Cloud Native Core Binding Support Function BSF locking
10 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Oracle Communications Cloud Native Core Binding Support Function 22.1.3. Affected is an unknown function of the component BSF. The manipulation leads to improper locking.
This vulnerability is traded as CVE-2022-24329. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-3447 | Google Chrome up to 106.0.5249.91 Custom Tabs Remote Code Execution
10 months 2 weeks ago
A vulnerability has been found in Google Chrome and classified as critical. Affected by this vulnerability is an unknown functionality of the component Custom Tabs. The manipulation leads to Remote Code Execution.
This vulnerability is known as CVE-2022-3447. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-24329 | Oracle Business Intelligence Enterprise Edition 5.9.0.0.0/6.4.0.0.0 Majel Mobile Service locking
10 months 2 weeks ago
A vulnerability classified as critical was found in Oracle Business Intelligence Enterprise Edition 5.9.0.0.0/6.4.0.0.0. This vulnerability affects unknown code of the component Majel Mobile Service. The manipulation leads to improper locking.
This vulnerability was named CVE-2022-24329. The attack can be initiated remotely. There is no exploit available.
vuldb.com